{ config, lib, pkgs, ... }: { imports = [ ./dyndns.nix ]; # https://github.com/NixOS/nixpkgs/issues/210807#issuecomment-1383263210 options.services.nginx.virtualHosts = lib.mkOption { type = lib.types.attrsOf (lib.types.submodule { config.acmeRoot = lib.mkDefault null; }); }; config = { security.acme.acceptTerms = true; security.acme.defaults.email = "hostmaster@mou.fo"; # https://go-acme.github.io/lego/dns/exec/ security.acme.defaults.dnsProvider = "exec"; security.acme.defaults.credentialFiles = { "DDNS_FILE" = "/var/secrets/dyndns/"; }; security.acme.defaults.environmentFile = pkgs.writeText "lego.env" '' # While it can be helpful to follow CNAMEs to find the challenge domain, # this heuristic may not work with wildcard domains or DNAME. LEGO_DISABLE_CNAME_SUPPORT=1 EXEC_PATH=${pkgs.writers.writeBash "lego-exec" '' set -e fqdn=${config.networking.fqdn} challenge_fqdn=$2''${fqdn%%.*}.dynamic.''${fqdn#*.} unset update_rr if [[ $1 = present ]]; then update_rr="update add $challenge_fqdn. 300 TXT $3" fi ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DDNS_FILE}_$(< ''${DDNS_FILE}_basename).private <<. update delete $challenge_fqdn. TXT $update_rr send . if [[ $1 = present ]]; then sleep 5 fi ''} ''; }; }